Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We are trying to setup Cisco Identity Services Engine Passive Identity Connector using the admin guide 3.4 we have deployed 2 new servers runnintg the pic agents that are running on windows 2025 these are trying to query domain controllers running wi...
We are experiencing an issue with Cisco Secure Client when users connect from sites utilizing GovWifi (a local government service for accessing central services).Current Setup & Behavior:Split Tunneling: Enabled for Microsoft services.Internet Access...
Previously, we used eStreamer to send logs to an eNcore client on the syslog server. Now that eNcore has reached end-of-life, what is Cisco’s recommended approach, and how can we configure log forwarding to ensure our cybersecurity systems continue r...
We are attempting to allow Microsoft Intune traffic through our Firepower appliance running version 7.7.10. However, the traffic is being inspected by Snort and is reported as blacklisted. Even though the relevant objects, URLs, FQDNs, application fi...
In the process of getting Microsoft Intune workig but hit a wall with the cleints hitting"Drop-reason: (snort-blacklist) Packet is blacklisted by snort, Drop-location: frame inspect_dp_snort_snp_drop_frame_wcaller:61 flow (NA)/NA"A prefilter is no go...
Thanks for the reply Mark, but we are on patch 6 now I did ask TAC and they came back with this so got our server guys to take a look.The logs identify an authorization issue on both domain controllers, not a connectivity failure:error querying event...
We have resolved the logging issue. thanks fro all the replies.Option we used was in the advanced option within the ACP and created an Action alert this pushes the logs to the syslog server and includes the intrusion events.